Commvault security & compliance
An overview of Commvault's security posture — compliance, penetration testing, subprocessors, and data handling — verified on SOC2C (Listed).
SOC 2 statusSOC 2 Type II · Listed
FrameworksSOC 2 Type II, ISO 27001, FedRAMP, NIST CSF, PCI DSS, HIPAA, CSA STAR
Penetration testNot listed
Subprocessors13 listed
HostingAWS, GCP, Azure
Trust centerView
Security questions about Commvault
- Is Commvault secure?
- Security isn't a single yes/no, but Commvault is SOC 2 Type II compliant and holds SOC 2 Type II, ISO 27001, FedRAMP, NIST CSF, PCI DSS, HIPAA, CSA STAR. SOC2C verifies its compliance posture and shows how strongly each fact is proven.
- Does Commvault have a bug bounty or vulnerability disclosure program?
- Commvault hasn't listed a bug bounty or vulnerability disclosure program on SOC2C. Many companies accept security reports at security@commvault.com or via a /security page (Commvault lists a security contact).
- Who are Commvault's subprocessors?
- Commvault lists 13 subprocessors on its trust center, including Commvault Systems Limited (UK), Commvault Systems (India) Pty. Ltd, Commvault Systems (Egypt) LLC, Commvault Systems (Australia) Pty. Ltd, Microsoft Corporation. Buyers use this for fourth-party risk review.
- Where does Commvault host or store data?
- Commvault hosts on AWS, GCP, Azure, and handles Customer personally identifiable information, Employee personally identifiable information, Credit card information. Data residency details are on its trust center.
- Where is Commvault's trust center or security page?
- Commvault's trust center is at https://trust.commvault.com. Its verified SOC 2 status, frameworks, and documents are summarized on its SOC2C profile.